Vulnerability Details CVE-2025-12343
A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.5%
CVSS Severity
CVSS v3 Score 3.3
Products affected by CVE-2025-12343
-
cpe:2.3:a:ffmpeg:ffmpeg:6.1
-
cpe:2.3:a:ffmpeg:ffmpeg:6.1.1
-
cpe:2.3:a:ffmpeg:ffmpeg:6.1.2
-
cpe:2.3:a:ffmpeg:ffmpeg:6.1.3
-
cpe:2.3:a:ffmpeg:ffmpeg:6.1.4
-
cpe:2.3:a:ffmpeg:ffmpeg:6.2
-
cpe:2.3:a:ffmpeg:ffmpeg:7.0
-
cpe:2.3:a:ffmpeg:ffmpeg:7.0.1
-
cpe:2.3:a:ffmpeg:ffmpeg:7.0.2
-
cpe:2.3:a:ffmpeg:ffmpeg:7.0.3
-
cpe:2.3:a:ffmpeg:ffmpeg:7.1
-
cpe:2.3:a:ffmpeg:ffmpeg:7.1.1
-
cpe:2.3:a:ffmpeg:ffmpeg:7.1.2
-
cpe:2.3:a:ffmpeg:ffmpeg:7.1.3
-
cpe:2.3:a:ffmpeg:ffmpeg:7.2
-
cpe:2.3:a:ffmpeg:ffmpeg:8.0
-
cpe:2.3:a:ffmpeg:ffmpeg:8.0.1